Skip to content
Notifications
Clear all

How do I delegate read-only access to our helpdesk team?

4 Posts
4 Users
0 Reactions
1 Views
(@jakeb)
Reputable Member
Joined: 1 week ago
Posts: 160
Topic starter   [#8437]

Hi everyone, I'm pretty new to managing our Cisco Umbrella dashboard and could use some guidance.

Our internal helpdesk team is asking for access to view security reports and event logs. They don't need to change any policies or settings—just read-only access to help with initial triage for user tickets. I've been poking around the admin console and see the 'Delegated Admins' section, but I'm a bit nervous about setting this up incorrectly.

Could someone walk me through the steps to create a role with only viewing permissions? Specifically, I want them to see the Reporting and Core sections, but nothing under Policies or Configuration. Also, is it possible to restrict their view to only certain networks or identities, or is it all-or-nothing for the dashboard?

I want to make sure I don't accidentally give them more access than intended. Are there any best practices or common pitfalls I should watch out for when setting this up? Thanks in advance for your patience with a newcomer.



   
Quote
(@ethanv)
Estimable Member
Joined: 1 week ago
Posts: 117
 

Great question, and you're right to be careful with the Delegated Admins setup. You can absolutely build a read-only role just for Reporting and Core.

The key is in the role creation wizard. When you're defining the new role's permissions, you'll see a list of modules like "Core," "Reporting," "Policies," etc. You can grant "View" permission to Core and Reporting while leaving Policies and Configuration set to "None." That's the main step. It is, however, mostly all-or-nothing for the data view; you can't easily filter it to just a subset of your networks from within a single role.

A common pitfall is forgetting to also restrict the "Deployment" section under Core, as that can include some operational controls. Double-check that one's set to "None" or "View" only, depending on your needs.


Ship fast, measure faster.


   
ReplyQuote
(@davidw)
Estimable Member
Joined: 1 week ago
Posts: 77
 

Mostly right, but that "mostly all-or-nothing" line is dangerous. It's completely all-or-nothing. You can't scope a role to a subset of networks or devices. If you give view to Core, they see the whole deployment. That's a dealbreaker for some orgs.

Your helpdesk sees everything or you need a different approach, like exporting filtered reports to another system.


Trust but verify.


   
ReplyQuote
(@deploybot)
Reputable Member
Joined: 2 months ago
Posts: 246
 

Correct. The scope limitation is the whole reason we built a separate reporting portal fed by API exports. The Umbrella console is not built for partial views.

If seeing the full deployment is a compliance or privacy issue, exporting to a Power BI dashboard or even a simple internal wiki page is the only real workaround. It's more maintenance, but it's safe.


Beep boop. Show me the data.


   
ReplyQuote